top of page

Cyber Insurance

A breach doesn't have to start with your own systems to become your problem. If a vendor you rely on gets compromised, or your own platform is hit directly, cyber insurance covers the forensics, legal fees, notification costs and business interruption that follow.

For financial services firms handling client funds and sensitive data, a cyber incident is a matter of when, not if.

What is cyber insurance?

Cyber insurance covers the direct and indirect costs of a data breach, ransomware attack or other cyber incident. That includes forensic investigation, legal counsel, customer and regulator notification, credit monitoring, business interruption and, in many cases, the ransom itself.

It also covers liability if a client, partner or regulator alleges your company failed to protect their data.

City Skyline View

Why is cyber insurance necessary?

Financial services firms are a preferred target precisely because of what they hold, client financial data, transaction records and access to funds. And the exposure often does not start in-house.

In March 2022, Mailchimp, an email marketing platform used broadly across the tech and financial sectors, disclosed that attackers had used social engineering to compromise employee credentials and access customer accounts.

Mailchimp confirmed the incident specifically targeted "users in industries related to cryptocurrency and finance," and the stolen data was used to launch phishing campaigns against those companies' own customers. It was the second of three such incidents Mailchimp disclosed within twelve months. For any financial services firm using third-party platforms, a vendor's breach can become your breach.

Source: Mailchimp, "Information about a Recent Mailchimp Security Incident," official company newsroom post, March 2022.

What does cyber insurance cover?

  • Forensic investigation to determine the scope and cause of a breach

  • Legal fees and regulatory defense costs

  • Customer and regulator notification costs

  • Credit monitoring and identity protection services for affected individuals

  • Business interruption and lost income during and after an incident

  • Ransom payments and negotiation costs, where permitted

  • Liability claims from clients or partners alleging inadequate data protection

Signed Document
Business Document Review

What is not covered by cyber insurance?

  • Bodily injury or property damage (covered under General Liability)

  • Intentional or criminal acts by the insured company

  • Loss of value from a company's own intellectual property or trade secrets, in most standard policies

  • Improvements to security infrastructure made after an incident, as a preventative measure rather than a response to a covered claim

  • Reputational harm that isn't tied to a direct financial loss

Real-World Examples

According to IBM's 2025 Cost of a Data Breach Report, the global average cost of a data breach is $4.44 million, and in the United States specifically, the average reaches $10.22 million, the highest of any country measured.

Source: IBM Security and Ponemon Institute, Cost of a Data Breach Report 2025, published August 2025.

Is it worth getting cyber insurance?

For a financial services firm, yes, and it is increasingly treated as a baseline requirement rather than an option. Institutional clients, banking partners and enterprise customers are increasingly requiring proof of cyber coverage before signing a contract.

Given that the average U.S. breach now costs over $10 million, and that most small business breaches involve ransomware, the cost of the policy is small relative to the cost of an uncovered incident.

bottom of page